CVS Pharmacy, Inc.
bd_fc4af90e78d486c1 · schema v1 · pii pii-v1
Full breach record for CVS Pharmacy, Inc. →9 incidents on fileCVS Pharmacy, Inc. disclosed an unauthorized intrusion into the systems of its independent vendor, PNI Digital Media, which hosted the CVSPhoto.com website. The intrusion occurred between June 2014 and July 2015 and potentially resulted in the unauthorized acquisition of payment card numbers, verification codes, names, addresses, phone numbers, email addresses, and usernames/passwords. CVS took down the website, engaged forensic investigators, and offered one year of credit monitoring to affected customers.
J jump to incidentP pin to compareR raw source
Incident timeline
Jun 1, 2014
Begins
Jul 1, 2015
Discovered
Sep 11, 2015
Filed
vs. sector median
+3 wks slower
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- Massachusetts State AGbd_8534ceb654eebac52015-09-11Verified
- New Hampshire State AGbd_0146674d7aa449bb2015-09-10 · +1dVerified
- South Carolina State AGbd_c170bb3c6ed5a8cb2015-09-14 · +3dVerified
Filing propagation · 4 filings · 4 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.